Privacy
Draft for solicitor review — not yet in force
Working draft prepared for solicitor review before launch. [FERN LTD] will be registered with the ICO before this notice takes effect (registration [NUMBER]).
1. Who is responsible
[FERN LTD], registered in England and Wales ([NUMBER], [ADDRESS]), is the data controller for fernapp.co.uk. Contact: [hello@fernapp.co.uk]. Our data is hosted in the United Kingdom (AWS London) by our database provider, Supabase.
2. What we collect, and why
Your account — email address (to sign you in; we use passwordless magic links, so there is no password to store), display name, @handle, profile photo, bio, and the rough area you choose to show. Legal basis: performing our contract with you.
Your location — your postcode and its coordinates, used to measure distances and place map pins. These are held privately: they are never shown to other users, and the position published for a listing is deliberately offset by several hundred metres so it does not identify your address. Photo location data (EXIF GPS) is stripped when photos are processed on upload. Legal basis: contract.
Your activity — listings and their photos, messages with other users, offers, orders, reviews, who you follow, saved-search alerts you create, and notification records. Aggregate view counts on listings are not tied to who viewed. Legal basis: contract; for moderation and fraud prevention, legitimate interests.
Payments — handled by Stripe. Card numbers go directly to Stripe and never touch our servers; we hold the transaction record (amounts, parties, status). Sellers complete identity checks with Stripe, not with us. Legal bases: contract and legal obligation (including HMRC digital-platform reporting rules).
We do not run advertising or third-party analytics, and we do not sell personal data.
3. What is public by design
Fern is a marketplace between strangers, so some information is deliberately public: your display name, @handle, photo, bio, rough area, follower and following lists, your ratings — shown separately as a seller and as a buyer — and the text of reviews. Because reviews name their author, a review you write as a buyer reveals that you bought that item from that seller. Your email, postcode and exact location are never public.
4. AI features
If you tap “fill this in for me” when listing, the photos you chose are sent to Anthropic (our AI provider) to draft the listing. Under our agreement, Anthropic does not use this data to train its models. The feature runs only when you press the button — photos are not otherwise sent. Legal basis: contract (you asked for the draft).
5. Who processes data for us
Supabase (database, authentication and photo storage — UK/London), Vercel (web hosting and delivery), Stripe (payments), Resend (transactional email), Anthropic (AI listing drafts, only as described above), postcodes.io (turning a postcode into coordinates — the postcode is the only data sent), and OpenFreeMap (map tiles — your device requests tiles directly, which exposes your IP address to them as with any website asset). Where a processor is outside the UK, transfers rely on the UK International Data Transfer Agreement or Addendum. [SOLICITOR TO CONFIRM TRANSFER WORDING PER PROCESSOR.]
6. Messages and moderation
Messages are private between the two of you. Our team reads a conversation only when investigating a report, a dispute over held payment, or suspected fraud or off-platform payment — and only that conversation. Legal basis: legitimate interests in keeping the marketplace safe.
7. Email, and how to stop it
We send transactional email — new messages, offers, order updates, review notifications, and alerts for saved searches you created. You can switch all email off in Settings; in-app notifications continue, because they are how the product tells you what happened. We do not send marketing email. If that changes it will be opt-in and separately controlled.
8. Cookies and device storage
We use only strictly necessary storage in your browser: your sign-in session, your place in the app's navigation, and a note of which listings you have already viewed this session (so views are not double-counted). No advertising cookies, no tracking cookies, no analytics scripts. Because all storage is strictly necessary, there is no cookie banner to click.
9. How long we keep things
Your data stays while your account is open. Listings you remove stay in your account (recoverable) until you delete them or your account. Transaction records are kept [6] years after the transaction for tax, accounting and platform-reporting obligations, even after account deletion. Server logs held by our hosting providers expire on their standard schedules.
10. Deleting your account
Settings → delete account, any time. If you have never bought or sold: everything is erased — profile, listings, photos, messages, favourites, follows, saved searches and your sign-in itself. If you have transacted: your personal data is erased or anonymised (name, handle, photo, bio, location, follows, alerts, messages you sent), your listings come down, and your sign-in is permanently disabled — but the bare transaction record survives against an anonymised profile, because the other party keeps their receipt and the law requires us to keep it. Your email address is released, so you could start again fresh.
11. Your rights
You have the rights UK GDPR gives you: access to your data, correction, erasure, restriction, portability, and objection to processing based on legitimate interests. Most of it you can see and edit directly in the app; for a copy of your data or anything you cannot do yourself, email [hello@fernapp.co.uk] and we will respond within one month. If you are unhappy with how we handle your data you can complain to the Information Commissioner's Office (ico.org.uk), though we would rather you told us first.
12. Changes
If this notice changes materially we will tell you in the app before the change takes effect. This notice forms part of our terms.
Draft v2 — prepared 29 July 2026 for solicitor review alongside the terms. Bracketed items for the founders: company details, ICO registration number, retention period confirmation, transfer wording per processor. Note for review: self-serve data export is not yet built — until it is, exports are handled by email, and the one-month response commitment above is the backstop.